PCI ISA Exam 200 Questions and Correct Answers
1: What is the primary purpose of the PCI DSS?
A. To regulate credit card interest rates
B. To protect cardholder data and reduce payment card fraud
C. To mandate specific security products
D. To replace national data protection laws
CORRECT ANSWER: B. To protect cardholder data and reduce payment card fraud
Rationale: The Payment Card Industry Data Security Standard (PCI DSS) was developed to
enhance payment account security and reduce fraud by establishing baseline security controls
for entities that store, process, or transmit cardholder data.
2: Which entities are required to comply with PCI DSS?
A. Only large merchants
B. Only payment processors
C. Any entity that stores, processes, or transmits cardholder data
D. Only banks
CORRECT ANSWER: C. Any entity that stores, processes, or transmits cardholder data
Rationale: PCI DSS applies to all entities—merchants, service providers, processors, and
financial institutions—that handle cardholder data, regardless of size or transaction volume.
3: What does "cardholder data" (CHD) include under PCI DSS?
A. Only the primary account number (PAN)
B. PAN plus cardholder name, expiration date, and/or service code
C. Only sensitive authentication data
D. Only tokenized data
CORRECT ANSWER: B. PAN plus cardholder name, expiration date, and/or service code
Rationale: Cardholder data includes the Primary Account Number (PAN) and may include
cardholder name, expiration date, and/or service code when stored with the PAN. Sensitive
authentication data (full track data, CAV2/CVC2/CVV2/CID, PINs) must never be stored post-
authorization.
4: Which PCI DSS requirement addresses network security controls?
,A. Requirement 1
B. Requirement 3
C. Requirement 8
D. Requirement 12
CORRECT ANSWER: A. Requirement 1
Rationale: Requirement 1 focuses on installing and maintaining network security controls,
including firewalls, to protect the cardholder data environment (CDE).
5: What is the minimum frequency for reviewing firewall rule sets per PCI DSS?
A. Monthly
B. Quarterly
C. Every 6 months
D. Annually
CORRECT ANSWER: C. Every 6 months
Rationale: PCI DSS Requirement 1.2.2 requires firewall rule sets to be reviewed at least every six
months to ensure they remain necessary and appropriate.
6: Which of the following is considered sensitive authentication data that must NOT be stored
post-authorization?
A. Cardholder name
B. Primary Account Number (PAN)
C. Full track data
D. Expiration date
CORRECT ANSWER: C. Full track data
Rationale: Full track data (from the magnetic stripe or chip equivalent) is sensitive
authentication data that must never be stored after authorization, per PCI DSS Requirement 3.2.
7: What is the primary purpose of segmentation in PCI DSS compliance?
A. To reduce network costs
B. To isolate the cardholder data environment from other networks
C. To increase internet speed
D. To simplify user access
CORRECT ANSWER: B. To isolate the cardholder data environment from other networks
,Rationale: Segmentation reduces the scope of PCI DSS by isolating systems that store, process,
or transmit cardholder data from other network segments, limiting the systems subject to
assessment.
8: Which encryption standard is commonly accepted for protecting stored cardholder data?
A. DES
B. AES with strong key management
C. ROT13
D. Base64 encoding
CORRECT ANSWER: B. AES with strong key management
Rationale: PCI DSS Requirement 3.5 requires strong cryptography (e.g., AES) with robust key
management practices to protect stored cardholder data. Weak algorithms like DES are not
acceptable.
9: What is the minimum key strength required for RSA encryption under PCI DSS?
A. 512 bits
B. 1024 bits
C. 2048 bits or higher
D. No minimum
CORRECT ANSWER: C. 2048 bits or higher
Rationale: PCI DSS requires cryptographic keys to be strong; for RSA, keys must be at least 2048
bits to be considered strong cryptography.
10: Which PCI DSS requirement addresses access control?
A. Requirement 2
B. Requirement 5
C. Requirement 7
D. Requirement 10
CORRECT ANSWER: C. Requirement 7
Rationale: Requirement 7 focuses on restricting access to cardholder data by business need-to-
know, implementing role-based access controls.
11: What is the purpose of unique IDs for personnel with computer access?
A. To simplify login
B. To enable accountability and traceability of actions
, C. To reduce password complexity
D. To allow shared accounts
CORRECT ANSWER: B. To enable accountability and traceability of actions
Rationale: PCI DSS Requirement 8.1 requires unique IDs to ensure actions can be traced to
individual users, supporting accountability and forensic investigations.
12: How often must user access rights be reviewed per PCI DSS?
A. Weekly
B. Monthly
C. At least quarterly
D. Annually
CORRECT ANSWER: C. At least quarterly
Rationale: Requirement 7.2.3 requires user access rights to be reviewed at least quarterly to
ensure access remains appropriate and necessary.
13: Which authentication factor is considered "something you have"?
A. Password
B. Fingerprint
C. Smart card or token
D. PIN
CORRECT ANSWER: C. Smart card or token
Rationale: Multi-factor authentication requires at least two of: something you know (password),
something you have (token), or something you are (biometric). Smart cards/tokens represent
"something you have."
14: What is the minimum password complexity required by PCI DSS?
A. 6 characters, any type
B. 7 characters with numeric only
C. At least 7 characters with numeric and alphabetic
D. No requirements
CORRECT ANSWER: C. At least 7 characters with numeric and alphabetic
Rationale: PCI DSS Requirement 8.3.6 requires passwords/passphrases to be at least 7
characters long and contain both numeric and alphabetic characters (or equivalent complexity).
15: Which PCI DSS requirement addresses malware protection?
1: What is the primary purpose of the PCI DSS?
A. To regulate credit card interest rates
B. To protect cardholder data and reduce payment card fraud
C. To mandate specific security products
D. To replace national data protection laws
CORRECT ANSWER: B. To protect cardholder data and reduce payment card fraud
Rationale: The Payment Card Industry Data Security Standard (PCI DSS) was developed to
enhance payment account security and reduce fraud by establishing baseline security controls
for entities that store, process, or transmit cardholder data.
2: Which entities are required to comply with PCI DSS?
A. Only large merchants
B. Only payment processors
C. Any entity that stores, processes, or transmits cardholder data
D. Only banks
CORRECT ANSWER: C. Any entity that stores, processes, or transmits cardholder data
Rationale: PCI DSS applies to all entities—merchants, service providers, processors, and
financial institutions—that handle cardholder data, regardless of size or transaction volume.
3: What does "cardholder data" (CHD) include under PCI DSS?
A. Only the primary account number (PAN)
B. PAN plus cardholder name, expiration date, and/or service code
C. Only sensitive authentication data
D. Only tokenized data
CORRECT ANSWER: B. PAN plus cardholder name, expiration date, and/or service code
Rationale: Cardholder data includes the Primary Account Number (PAN) and may include
cardholder name, expiration date, and/or service code when stored with the PAN. Sensitive
authentication data (full track data, CAV2/CVC2/CVV2/CID, PINs) must never be stored post-
authorization.
4: Which PCI DSS requirement addresses network security controls?
,A. Requirement 1
B. Requirement 3
C. Requirement 8
D. Requirement 12
CORRECT ANSWER: A. Requirement 1
Rationale: Requirement 1 focuses on installing and maintaining network security controls,
including firewalls, to protect the cardholder data environment (CDE).
5: What is the minimum frequency for reviewing firewall rule sets per PCI DSS?
A. Monthly
B. Quarterly
C. Every 6 months
D. Annually
CORRECT ANSWER: C. Every 6 months
Rationale: PCI DSS Requirement 1.2.2 requires firewall rule sets to be reviewed at least every six
months to ensure they remain necessary and appropriate.
6: Which of the following is considered sensitive authentication data that must NOT be stored
post-authorization?
A. Cardholder name
B. Primary Account Number (PAN)
C. Full track data
D. Expiration date
CORRECT ANSWER: C. Full track data
Rationale: Full track data (from the magnetic stripe or chip equivalent) is sensitive
authentication data that must never be stored after authorization, per PCI DSS Requirement 3.2.
7: What is the primary purpose of segmentation in PCI DSS compliance?
A. To reduce network costs
B. To isolate the cardholder data environment from other networks
C. To increase internet speed
D. To simplify user access
CORRECT ANSWER: B. To isolate the cardholder data environment from other networks
,Rationale: Segmentation reduces the scope of PCI DSS by isolating systems that store, process,
or transmit cardholder data from other network segments, limiting the systems subject to
assessment.
8: Which encryption standard is commonly accepted for protecting stored cardholder data?
A. DES
B. AES with strong key management
C. ROT13
D. Base64 encoding
CORRECT ANSWER: B. AES with strong key management
Rationale: PCI DSS Requirement 3.5 requires strong cryptography (e.g., AES) with robust key
management practices to protect stored cardholder data. Weak algorithms like DES are not
acceptable.
9: What is the minimum key strength required for RSA encryption under PCI DSS?
A. 512 bits
B. 1024 bits
C. 2048 bits or higher
D. No minimum
CORRECT ANSWER: C. 2048 bits or higher
Rationale: PCI DSS requires cryptographic keys to be strong; for RSA, keys must be at least 2048
bits to be considered strong cryptography.
10: Which PCI DSS requirement addresses access control?
A. Requirement 2
B. Requirement 5
C. Requirement 7
D. Requirement 10
CORRECT ANSWER: C. Requirement 7
Rationale: Requirement 7 focuses on restricting access to cardholder data by business need-to-
know, implementing role-based access controls.
11: What is the purpose of unique IDs for personnel with computer access?
A. To simplify login
B. To enable accountability and traceability of actions
, C. To reduce password complexity
D. To allow shared accounts
CORRECT ANSWER: B. To enable accountability and traceability of actions
Rationale: PCI DSS Requirement 8.1 requires unique IDs to ensure actions can be traced to
individual users, supporting accountability and forensic investigations.
12: How often must user access rights be reviewed per PCI DSS?
A. Weekly
B. Monthly
C. At least quarterly
D. Annually
CORRECT ANSWER: C. At least quarterly
Rationale: Requirement 7.2.3 requires user access rights to be reviewed at least quarterly to
ensure access remains appropriate and necessary.
13: Which authentication factor is considered "something you have"?
A. Password
B. Fingerprint
C. Smart card or token
D. PIN
CORRECT ANSWER: C. Smart card or token
Rationale: Multi-factor authentication requires at least two of: something you know (password),
something you have (token), or something you are (biometric). Smart cards/tokens represent
"something you have."
14: What is the minimum password complexity required by PCI DSS?
A. 6 characters, any type
B. 7 characters with numeric only
C. At least 7 characters with numeric and alphabetic
D. No requirements
CORRECT ANSWER: C. At least 7 characters with numeric and alphabetic
Rationale: PCI DSS Requirement 8.3.6 requires passwords/passphrases to be at least 7
characters long and contain both numeric and alphabetic characters (or equivalent complexity).
15: Which PCI DSS requirement addresses malware protection?